Welcome to the GoFuckYourself.com - Adult Webmaster Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features. By joining our free community you will have access to post topics, communicate privately with other members (PM), respond to polls, upload content and access many other special features. Registration is fast, simple and absolutely free so please, join our community today!

If you have any problems with the registration process or your account login, please contact us.

Post New Thread Reply

Register GFY Rules Calendar
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >
Discuss what's fucking going on, and which programs are best and worst. One-time "program" announcements from "established" webmasters are allowed.

 
Thread Tools
Old 12-11-2012, 12:55 PM   #1
Heath
Confirmed User
 
Join Date: Sep 2008
Posts: 491
25-GPU cluster cracks every standard Windows password in <6 hours

arstechnica.com/security/2012/12/25-gpu-cluster-cracks-every-standard-windows-password-in-6-hours/

Quote:
A password-cracking expert has unveiled a computer cluster that can cycle through as many as 350 billion guesses per second. It's an almost unprecedented speed that can try every possible Windows passcode in the typical enterprise in less than six hours.

The five-server system uses a relatively new package of virtualization software that harnesses the power of 25 AMD Radeon graphics cards. It achieves the 350 billion-guess-per-second speed when cracking password hashes generated by the NTLM cryptographic algorithm that Microsoft has included in every version of Windows since Server 2003. As a result, it can try an astounding 958 combinations in just 5.5 hours, enough to brute force every possible eight-character password containing upper- and lower-case letters, digits, and symbols. Such password policies are common in many enterprise settings. The same passwords protected by Microsoft's LM algorithm?which many organizations enable for compatibility with older Windows versions?will fall in just six minutes.

The Linux-based GPU cluster runs the Virtual OpenCL cluster platform, which allows the graphics cards to function as if they were running on a single desktop computer. ocl-Hashcat Plus, a freely available password-cracking suite optimized for GPU computing, runs on top, allowing the machine to tackle at least 44 other algorithms at near-unprecedented speeds. In addition to brute-force attacks, the cluster can bring that speed to cracks that use a variety of other techniques, including dictionary attacks containing millions of words.

"What this cluster means is, we can do all the things we normally would with Hashcat, just at a greatly accelerated rate," Jeremi Gosney, the founder and CEO of Stricture Consulting Group, wrote in an e-mail to Ars. "We can attack hashes approximately four times faster than we could previously."

Gosney unveiled the machine last week at the Passwords^12 conference in Oslo, Norway. He previously used a computer equipped with four AMD Radeon HD6990 graphics cards that could make about 88 billion guesses per second against NTLM hashes. As Ars previously reported in a feature headlined "Why passwords have never been weaker?and crackers have never been stronger," Gosney used the machine to crack 90 percent of the 6.5 million password hashes belonging to users of LinkedIn. In addition to the power of his hardware, his attack was aided by a 500 million-strong word list and a variety of advanced programming rules.

Using the new cluster, the same attack would move about four times faster. That's because the machine is able to make about 63 billion guesses against SHA1, the algorithm used to hash the LinkedIn passwords, versus the 15.5 billion guesses his previous hardware was capable of. The cluster can try 180 billion combinations per second against the widely used MD5 algorithm, which is also about a four-fold improvement over his older system.

The speeds apply to so-called offline cracks, in which password lists are retrieved by hackers who exploit vulnerabilities on website or network servers. The passwords are typically stored using one-way cryptographic hash functions, which generate a unique string of characters for each unique string of plaintext. In theory, hashes can't be mathematically reversed. The only way to crack them is to run guesses through the same cryptographic function. When the output of a particular guess matches a hash in a compromised list, the corresponding password has been cracked.
Full Article : rstechnica.com/security/2012/12/25-gpu-cluster-cracks-every-standard-windows-password-in-6-hours/
__________________
Email - popuplace [at] yahoo [dot] com
Heath is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-11-2012, 01:15 PM   #2
NatalieK
Natalie K
 
NatalieK's Avatar
 
Industry Role:
Join Date: Apr 2010
Location: Spain
Posts: 19,376
Sounds like a piece of art
__________________
My official site Custom vids Make money & get into the businessFirst time girls
Skype: GspotProductions - "Converting traffic into income since 2005"
NatalieK is online now   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-11-2012, 01:25 PM   #3
PR_Dave
Confirmed User
 
PR_Dave's Avatar
 
Industry Role:
Join Date: Jul 2003
Location: Italy
Posts: 2,792
Would be good for video encoding
__________________
PR_Dave is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-11-2012, 02:35 PM   #4
bronco67
Too lazy to set a custom title
 
bronco67's Avatar
 
Join Date: Dec 2006
Posts: 29,032
So....why? Isn't there something more productive to do with all that computing power?
__________________
bronco67 is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-11-2012, 03:17 PM   #5
Why
MFBA
 
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
Quote:
Originally Posted by PR_Dave View Post
Would be good for video encoding
it would be fast, but poor quality. GPU encoding results in lesser quality then CPU encoding, due to the way they are built.

the difference in quality is actually noticeable to the naked eye.
Why is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-11-2012, 03:18 PM   #6
Why
MFBA
 
Industry Role:
Join Date: Mar 2003
Location: PNW
Posts: 7,230
and this is why hashes are bad. ;)

the computing power that is around today, all passwords are worthless.
Why is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-11-2012, 03:27 PM   #7
Rochard
Jägermeister Test Pilot
 
Rochard's Avatar
 
Industry Role:
Join Date: Dec 2001
Location: NORCAL
Posts: 73,602
So it can do 350 billion guesses per second... But my computer can only done one request every five seconds. So there goes that idea.
__________________
“The choice is no longer between right or left. The choice is between normal and crazy.”
- Sarah Huckabee Sanders

YNOT MAIL | THE BEST ADULT MAILING SOLUTION
Rochard is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-11-2012, 03:53 PM   #8
Ayla_SquareTurtle
Confirmed User
 
Ayla_SquareTurtle's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: 5000 full paysite reviews and counting
Posts: 3,550
Quote:
Originally Posted by Rochard View Post
So it can do 350 billion guesses per second... But my computer can only done one request every five seconds. So there goes that idea.
They use vulnerabilities in the OS to directly access the encrypted password file on your machine. Your machine doesn't have to be able to process the requests at that speed.
__________________
gone. long gone.

aylasquareturtle .."a"t".. gmail dawt com
Ayla_SquareTurtle is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-11-2012, 03:59 PM   #9
JP-pornshooter
Confirmed User
 
Join Date: Sep 2006
Location: westcoast usa
Posts: 4,007
doesnt most password protected application shut off after a few tries?
perhaps not software applications as much as "websites"?
__________________
"Obscenity is whatever gives the Judge an erection." -- Author Unknown
JP-pornshooter is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-11-2012, 04:02 PM   #10
Ayla_SquareTurtle
Confirmed User
 
Ayla_SquareTurtle's Avatar
 
Industry Role:
Join Date: Sep 2005
Location: 5000 full paysite reviews and counting
Posts: 3,550
Quote:
Originally Posted by JP-pornshooter View Post
doesnt most password protected application shut off after a few tries?
perhaps not software applications as much as "websites"?
Yes, but this is for cracking Windows which it does using the method I briefly explained above.
__________________
gone. long gone.

aylasquareturtle .."a"t".. gmail dawt com
Ayla_SquareTurtle is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-11-2012, 04:25 PM   #11
Robbie
Leaner, Meaner, Faster
 
Robbie's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: Vegas
Posts: 20,959
Quote:
Originally Posted by Why View Post
it would be fast, but poor quality. GPU encoding results in lesser quality then CPU encoding, due to the way they are built.

the difference in quality is actually noticeable to the naked eye.
You're dead wrong. GPU is better quality when rendering video.

You need to do some research. Why do you think that I and everyone else is using CUDA technology to render video using video cards with big GPU's?
__________________
-Robbie
ClaudiaMarie.Com
Robbie is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-11-2012, 04:28 PM   #12
Robbie
Leaner, Meaner, Faster
 
Robbie's Avatar
 
Industry Role:
Join Date: Aug 2002
Location: Vegas
Posts: 20,959
"GPU does a better job and is virtually identical to the master."

http://www.shawnlam.ca/2011/adobe-cs...-acceleration/
__________________
-Robbie
ClaudiaMarie.Com
Robbie is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-11-2012, 05:45 PM   #13
JP-pornshooter
Confirmed User
 
Join Date: Sep 2006
Location: westcoast usa
Posts: 4,007
Quote:
Originally Posted by Ayla_SquareTurtle View Post
Yes, but this is for cracking Windows which it does using the method I briefly explained above.
speaking of cracking, i have a couple wifi networks i like to test some cracking techniques on.. any suggestions?
strictly for testing purposes only.
__________________
"Obscenity is whatever gives the Judge an erection." -- Author Unknown
JP-pornshooter is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Old 12-11-2012, 05:55 PM   #14
GFED
Confirmed User
 
GFED's Avatar
 
Industry Role:
Join Date: May 2002
Posts: 8,098
Quote:
Originally Posted by JP-pornshooter View Post
speaking of cracking, i have a couple wifi networks i like to test some cracking techniques on.. any suggestions?
strictly for testing purposes only.
Backtrack + Reaver
GFED is offline   Share thread on Digg Share thread on Twitter Share thread on Reddit Share thread on Facebook Reply With Quote
Post New Thread Reply
Go Back   GoFuckYourself.com - Adult Webmaster Forum > >

Bookmarks



Advertising inquiries - marketing at gfy dot com

Contact Admin - Advertise - GFY Rules - Top

©2000-, AI Media Network Inc



Powered by vBulletin
Copyright © 2000- Jelsoft Enterprises Limited.